Vulnerability Note VU#115731
HP Tru64 UNIX "quot" contains buffer overflow (SSRT2191)
OverviewThe HP Tru64 UNIX implementation of "quot" contains a locally exploitable buffer overflow.
I. Description"quot" is used to summarize file system ownership. A locally exploitable buffer overflow in "quot" may permit a local attacker to gain elevated privileges and execute arbitrary code on a vulnerable host.II. ImpactA local user may be able to gain elevated privileges and execute arbitrary code.III. SolutionApply a patch.Systems Affected
References
http://wwss1pro.compaq.com/support/reference_library/viewdocument.asp?source=SRB0039W.xml&dt=11
Credit
This vulnerability was discovered by SNOsoft.
This document was written by Ian A Finlay & Jason A. Rafail.
Other Information
| Date Public | 05/22/2002 |
| Date First Published | 09/09/2002 12:55:06 PM |
| Date Last Updated | 09/09/2002 |
| CERT Advisory | |
| CVE Name | |
| Metric | 3.75 |
| Document Revision | 8 |
If you have feedback, comments, or additional information about this vulnerability, please send us
email.
|